低风险 — 风险评分 10/100
上次扫描:1 天前 重新扫描
10 /100
自动化营销推广师
Automated marketing agent for monitoring social media and generating professional responses on EU compliance, VAT, product selection, and logistics topics
This skill is a pure documentation file describing an automated social media marketing agent. No executable code, scripts, or malicious behaviors are present. The only inferred capability is skill_invoke for calling other skills.
技能名称自动化营销推广师
分析耗时23.3s
引擎pi
可以安装
Approve for use with standard monitoring. The skill raises ethical concerns around automated social media spamming but poses no technical security risks.

安全发现 1 项

严重性 安全发现 位置
低危
Automated social media engagement 文档欺骗
The skill describes automated posting and replying on social media platforms (Twitter, Reddit, LinkedIn, WeChat) without disclosing platform terms of service implications. This could be considered spam/automatic marketing which may violate platform policies.
全自动运行,无需人工干预
→ Consider adding a disclaimer about compliance with platform terms of service
SKILL.md:1
资源类型声明权限推断权限状态证据
文件系统 NONE NONE No file operations described or implemented
网络访问 NONE NONE Network access for social media posting is described conceptually but no code im…
命令执行 NONE NONE No shell commands or subprocess usage in the skill
技能调用 READ READ ✓ 一致 SKILL.md explicitly declares calling eu-compliance-advisor, eu-market-analyst, l…
环境变量 NONE NONE No environment variable access described
剪贴板 NONE NONE No clipboard access mentioned
浏览器 NONE NONE No browser automation described
数据库 NONE NONE No database access described

目录结构

1 文件 · 3.1 KB · 73 行
Markdown 1f · 73L
└─ 📝 SKILL.md Markdown 73L · 3.1 KB

安全亮点

✓ No executable code present - pure documentation file
✓ No base64, obfuscation, or anti-analysis techniques
✓ No credential harvesting or sensitive data access
✓ No network exfiltration or C2 communication
✓ No supply chain risks (no dependencies)
✓ All declared capabilities align with described functionality